Live data from Hacker News

AppStore Preferences can be unlocked by a local admin with any bogus password

openradar.appspot.com

91–100 of 190 posts

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#91
post #67
post #62

Earlier quoted context omitted.

Under a different lens, that implies that previously iOS-only engineers now must also become familiar with the macOS codebase, and so more able to contribute to it. Given the large number of those engineers compared to the previous size of the macOS team, this may help more than hurt macOS (as long as you assume the engineering teams are of equivalent quality.)

While it's tolerable to have engineers jumping between projects in, say, web frontend, I'd imagine that operating system security work is incredibly sensitive to programmer context-switching - you can't dive deep into the security model of a desktop system in your 20% time when you're working with an entirely different system (with a different CPU architecture) in your 80% time. Of course there will be some specializ…

Not sure if you're familiar with how iOS/OSX works.

For the Darwin team which is the actual core OS they would have to deal a lot with CPU architectures. But they again they have always dealt with this since back in the NeXT days. ARM and x86 isn't a big deal to manage and there isn't much evidence that something is wrong in that area.

For the UI teams i.e. System Frameworks, Cocoa, WindowServer etc. They are abstracted away from worrying about CPU architectures and they are the ones responsible for all the bugs we are seeing today. You can argue context switching is an issue here but again we don't have much visibility that iOS/OSX engineers are jumping back and forth every day.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#92

Earlier quoted context omitted.

Edit: El Capitain doesn't have the padlock on that pane Other panes validate the password correctly

On El Capitan, I don't even see a padlock on the AppStore prefpane.

That was my experience too... but after clicking around for a while & then going back to the App Store prefpane, I did see a padlock (unlocked) on the App Store prefpane. I haven't been able to reproduce it again, but it seems there's some kind of bug there even on El Capitan.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#93

This does not help at all for the drubbing that macOS High Sierra has been getting recently. Long term OS X users have been waiting for a Snow Leopard like release, but it seems like Apple isn’t taking as much care as required on security and stability on the Mac. Something has to give — either Apple’s organizational structure needs a change or Apple needs to abandon certain things completely instead of releasing sub…

I'm also a long-time Mac user, but I've really had about enough of this. Between the seemingly constant stream of security problems and the dumbing down of OSX (MacOS, whatever), I'm not sure I'm willing to pay a premium for this product anymore. At the same time the Apple seems to be dropping the ball, some of the more noob-friendly linux distros are starting to look very attractive. And while Apple still seems to h…

I never understand this line. How is MacOSX being dumbed down ?

It's largely the same OS since back in 10.0 DP1. Sure they try to lock down applications to those that are signed. But it's trivial to override and is great for OSX users that can't immediately identify malware.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#94
post #3

I have a feeling this isn't actually that High Sierra is that much worse, but more that people are now actively pen-testing macOS to find the next embarrassing bug. And that scares me even more because of the unknown of how long such bugs must've existed in the system. Is this Apple's Windows XP moment? (Like when MS stopped everything and did massive security training that resulted in XP SP 2 being worlds more secur…

High Sierra and Sierra both have enough disruptive bugs in them that I had to downgrade my 2012 Macbook Pro to El Capitan, which did not have those bugs. The most notable one for me was the massive regression in video drivers, that not only made many previously smooth-running games unplayable, but also caused several of the ordinary desktop apps I used to become unacceptably slow.

For me they broke automount (/etc/auto_master). It just... randomly takes root ownership of my smb shares. So I can't get to them. Then it randomly gives me ownership back. Crazy-making. Writing a Cocoa app right now to watch for kCFURLVolumeIsAutomountedKey errors and fix this bug myself.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#95

sorry if this is a dumb question, but: why is it unreasonable for a local admin to have the power to change AppStore preferences? without knowing much about the osx security model, this sounds like not a big deal?

this isn't a dangerous bug itself, it matters because it exists at all and raises concerns that similar bugs might exist in places where security might actually matter.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#96
post #80

Earlier quoted context omitted.

I'm also a long-time Mac user, but I've really had about enough of this. Between the seemingly constant stream of security problems and the dumbing down of OSX (MacOS, whatever), I'm not sure I'm willing to pay a premium for this product anymore. At the same time the Apple seems to be dropping the ball, some of the more noob-friendly linux distros are starting to look very attractive. And while Apple still seems to h…

> Slightly off topic, but one of the only software issues holding me back previously was 1Password compatibility on linux, but apparently, it is now available (1). Well, it's a Chrome extension. For some people (including yours truly), it's a deal breaker. I would suggest `password-store`[0] if you don't need to share your vault with anyone. [0] https://www.passwordstore.org

> if you don't need to share your vault with anyone

Or any other devices? Or even have rudimentary browser integration? How is this an alternative?

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#97
post #80

Earlier quoted context omitted.

I'm also a long-time Mac user, but I've really had about enough of this. Between the seemingly constant stream of security problems and the dumbing down of OSX (MacOS, whatever), I'm not sure I'm willing to pay a premium for this product anymore. At the same time the Apple seems to be dropping the ball, some of the more noob-friendly linux distros are starting to look very attractive. And while Apple still seems to h…

> Slightly off topic, but one of the only software issues holding me back previously was 1Password compatibility on linux, but apparently, it is now available (1). Well, it's a Chrome extension. For some people (including yours truly), it's a deal breaker. I would suggest `password-store`[0] if you don't need to share your vault with anyone. [0] https://www.passwordstore.org

Not quite what you're looking for, but Gonepass is a GTK read-only frontend for 1Password data. And Enpass is a complete replacement for 1Password.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#99
post #80

Earlier quoted context omitted.

> Slightly off topic, but one of the only software issues holding me back previously was 1Password compatibility on linux, but apparently, it is now available (1). Well, it's a Chrome extension. For some people (including yours truly), it's a deal breaker. I would suggest `password-store`[0] if you don't need to share your vault with anyone. [0] https://www.passwordstore.org

> if you don't need to share your vault with anyone Or any other devices? Or even have rudimentary browser integration? How is this an alternative?

Please check their website. You have extensions for Firefox, applications for Android, etc... It is an alternative, albeit not a drop-in replacement.

Re: AppStore Preferences can be unlocked by a local admin with any bogus password

#100
post #90
post #60

Earlier quoted context omitted.

Didn't use OSX back then, but I think there is a good distance between "not all that" and the security fiasco going on with High Sierra.

What about having it wipe all your user data? https://www.computerworld.com/article/2528936/mac-os-x/snow-...

On one hand you have massive data loss, a big issue for sure but something well understood, well known, that you can and should be prepared against in any case; you're never protected against: your computer being run over, or your house being on fire, or your HD suddenly dying. If I lose files by lack of backup, I can be angry at myself for not having done proper backups, whatever the source of the deletion, this is something I can remedy.

On the other you have giving access to your data to people who shouldn't have access, be it making them root, giving your encryption password in the hint field, ... You're not prepared against that, you have no mitigation and no remedy other than picking the right tool; either the tool you're using is secure or it is not.

Better everything gets deleted than someone not meant to have access getting it. And better something happens that I could insure myself against, than something against which I cannot do anything to protect myself.

Post reply on HN